CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Gnome2Gnome Remote Desktop Ubuntu LinuxJun 17, 2026 Jan 31, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. |
13Almalinux AmazonApple+10 more53500f Firmware 8300 Firmware8700 Firmware+50 moreJun 17, 2026 Jul 1, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more |
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snap...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Apport does not disable python crash handler before entering chroot |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to consume RAM in the Apport process |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 is_closing_session() allows users to create arbitrary tcp dbus connections |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to fill up apport.log |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack |
Apport can be tricked into connecting to arbitrary sockets as the root user |
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15...Show more |
4Canonical FedoraprojectLinux+1 more4Enterprise Linux FedoraLinux Kernel+1 moreJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more |
Race condition in snap-confine's must_mkdir_and_open_with_perms() |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 io_uring UAF, Unix SCM garbage collection |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free. |
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password. |
5Apple CanonicalDebian+2 more7Android Debian LinuxFedora+4 moreJun 17, 2026 Dec 8, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages w...Show more |